CVE-2012-1258

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
09/01/2020
Last modified:
21/11/2024

Description

cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges via the newuser, pwd, and selectedUserGroup parameters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:plixer:scrutinizer_netflow_\&_sflow_analyzer:*:*:*:*:*:*:*:* 9.0.1.19899 (excluding)